-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2019.0968
                          libsolv vulnerabilities
                               25 March 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           libsolv-tools
Publisher:         Ubuntu
Operating System:  Ubuntu
                   Linux variants
Impact/Access:     Denial of Service -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2018-20534 CVE-2018-20533 CVE-2018-20532

Original Bulletin: 
   http://www.ubuntu.com/usn/usn-3916-1

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Ubuntu. It is recommended that administrators 
         running libsolv-tools check for an updated version of the software 
         for their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

Ubuntu Security Notice USN-3916-1
March 22, 2019

libsolv vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

- - Ubuntu 18.10

Summary:

Libzip could be made to crash if it received specially crafted input.

Software Description:
- - libsolv: A dependency solver using a satisfiablility algorithm

Details:

It was discovered that libsolv incorrectly handled certain malformed input.
If a user or automated system were tricked into opening a specially crafted 
file, applications that rely on libsolv could be made to crash, resulting 
in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
  libsolv-tools                   0.6.35-2ubuntu0.18.10.1
  libsolv0                        0.6.35-2ubuntu0.18.10.1
  libsolvext0                     0.6.35-2ubuntu0.18.10.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3916-1
  CVE-2018-20532, CVE-2018-20533, CVE-2018-20534

Package Information:
  https://launchpad.net/ubuntu/+source/libsolv/0.6.35-2ubuntu0.18.10.1

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXJgoY2aOgq3Tt24GAQg0tw//STNn3OCVxOG9hCPCI7DaE+7lvSgTR2EL
yyp25TgnvyN3D1Mt0nJTQftDirUFJ7SgExnMSxgLg1yByaxIStXvLzHMHMG69zP8
JeAt5OCM20Sw69aOPAsgsf4uD9rYMm2jwunJfsCv+ejrhx/BBzsEmsqKFHI3+/8r
Bo7YLLh9eusrIrpdqOQZs+Mt+fiWKyPk5JNvlf7x6W7IKMiYprJFvjLIsf7n/3ka
fw+gVwFdTaptSgijHvpwNyLF21uXWeuaNIKOhfDk57hXDvwlLOkYnqodkQErRNG5
2q92g4+cqtKsogZuAtu/DZ9ZNul1qIj6Xk4O8jjDNez8cKssMgG15y2lWeBW2m3J
dDasldSMCtACmd4/Lijn8n8zZHPNHSQkuMb8jJrIW3FWmOg2/nnHJgjtFK0cDB82
C/OI/7veN+Ap0UECq9ce9GOMLtPJINzSs1F8wEQzFK45Z41D6NJsqLkFTDilRQoM
ZLnGkyTzUlatnEGc26xa5adxsjB1pEZgVYBiE8qrOfCy7A4lwQKqFfcZOv/fFL1S
j4loM78nmMRQc2T7OH7BE+D/bY1J7wo00JjMv5ytxKuYrHiFxPFAel9K0/9+Yl6R
fnspRDMok6fg35S0uq7CpoW5IwzHAgqGJ+Sm+29gtiE4VO3xcciN46CjzbQUPHls
WPa3Z/uMnJs=
=x/K0
-----END PGP SIGNATURE-----